CRITICAL
CVE-2024-50623
CVSS
9.8
KEV
Description
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.
Summary dbcve.org
This is an unrestricted file upload and download vulnerability in Cleo Harmony, VLTrader, and LexiCom (all versions before 5.8.0.21) that allows attackers to upload malicious files to the system without proper restrictions, potentially leading to remote code execution.
Mitigation
Upgrade to version 5.8.0.21 or later for all affected products. If immediate patching is not possible, implement network segmentation and restrict file upload functionality to trusted sources only.
Weakness (CWE)
CWE-434
Unrestricted File Upload
EPSS Score
98.61%
Probability of exploitation in next 30 days
99.9th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.